Total
21765 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2013-5326 | 1 Adobe | 1 Coldfusion | 2020-09-04 | 3.5 LOW | N/A |
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 9.0 before Update 12, 9.0.1 before Update 11, 9.0.2 before Update 6, and 10 before Update 12, when the CFIDE directory is available, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors related to the logviewer directory. | |||||
CVE-2020-25121 | 1 Vbulletin | 1 Vbulletin | 2020-09-03 | 3.5 LOW | 4.8 MEDIUM |
The Admin CP in vBulletin 5.6.3 allows XSS via the Paid Subscription Email Notification field in the Options. | |||||
CVE-2020-25117 | 1 Vbulletin | 1 Vbulletin | 2020-09-03 | 3.5 LOW | 4.8 MEDIUM |
The Admin CP in vBulletin 5.6.3 allows XSS via a Junior Member Title to User Title Manager. | |||||
CVE-2020-25115 | 1 Vbulletin | 1 Vbulletin | 2020-09-03 | 3.5 LOW | 4.8 MEDIUM |
The Admin CP in vBulletin 5.6.3 allows XSS via an Occupation Title or Description to User Profile Field Manager. | |||||
CVE-2020-25116 | 1 Vbulletin | 1 Vbulletin | 2020-09-03 | 3.5 LOW | 4.8 MEDIUM |
The Admin CP in vBulletin 5.6.3 allows XSS via an Announcement Title to Channel Manager. | |||||
CVE-2020-25119 | 1 Vbulletin | 1 Vbulletin | 2020-09-03 | 3.5 LOW | 4.8 MEDIUM |
The Admin CP in vBulletin 5.6.3 allows XSS via a Title of a Child Help Item in the Login/Logoff part of the User Manual. | |||||
CVE-2020-25120 | 1 Vbulletin | 1 Vbulletin | 2020-09-03 | 3.5 LOW | 4.8 MEDIUM |
The Admin CP in vBulletin 5.6.3 allows XSS via the admincp/search.php?do=dosearch URI. | |||||
CVE-2020-25118 | 1 Vbulletin | 1 Vbulletin | 2020-09-03 | 3.5 LOW | 4.8 MEDIUM |
The Admin CP in vBulletin 5.6.3 allows XSS via a Style Options Settings Title to Styles Manager. | |||||
CVE-2020-25122 | 1 Vbulletin | 1 Vbulletin | 2020-09-03 | 3.5 LOW | 4.8 MEDIUM |
The Admin CP in vBulletin 5.6.3 allows XSS via a Rank Type to User Rank Manager. | |||||
CVE-2020-25123 | 1 Vbulletin | 1 Vbulletin | 2020-09-03 | 3.5 LOW | 4.8 MEDIUM |
The Admin CP in vBulletin 5.6.3 allows XSS via a Smilie Title to Smilies Manager. | |||||
CVE-2020-25124 | 1 Vbulletin | 1 Vbulletin | 2020-09-03 | 3.5 LOW | 4.8 MEDIUM |
The Admin CP in vBulletin 5.6.3 allows XSS via an admincp/attachment.php&do=rebuild&type= URI. | |||||
CVE-2020-23814 | 1 Xuxueli | 1 Xxl-job | 2020-09-03 | 4.3 MEDIUM | 6.1 MEDIUM |
Multiple cross-site scripting (XSS) vulnerabilities in xxl-job v2.2.0 allow remote attackers to inject arbitrary web script or HTML via (1) AppName and (2)AddressList parameter in JobGroupController.java file. | |||||
CVE-2012-3341 | 1 Ibm | 1 Infosphere Guardium | 2020-09-03 | 3.5 LOW | 5.4 MEDIUM |
IBM InfoSphere Guardium 7.0, 8.0, 8.01, and 8.2 is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability using a specially-crafted URL to execute script in a victim's Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials. IBM X-Force ID: 78294. | |||||
CVE-2020-3466 | 1 Cisco | 1 Dna Center | 2020-09-03 | 4.3 MEDIUM | 6.1 MEDIUM |
Multiple vulnerabilities in the web-based management interface of Cisco DNA Center software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. The vulnerabilities exist because the web-based management interface on an affected device does not properly validate user-supplied input. An attacker could exploit these vulnerabilities by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. | |||||
CVE-2020-24314 | 1 Rss Feed Widget Project | 1 Rss Feed Widget | 2020-09-03 | 4.3 MEDIUM | 6.1 MEDIUM |
Fahad Mahmood RSS Feed Widget Plugin v2.7.9 and lower does not sanitize the value of the "t" GET parameter before echoing it back out inside an input tag. This results in a reflected XSS vulnerability that attackers can exploit with a specially crafted URL. | |||||
CVE-2020-24313 | 1 Etoilewebdesign | 1 Ultimate Appointment Booking \& Scheduling | 2020-09-03 | 4.3 MEDIUM | 6.1 MEDIUM |
Etoile Web Design Ultimate Appointment Booking & Scheduling WordPress Plugin v1.1.9 and lower does not sanitize the value of the "Appointment_ID" GET parameter before echoing it back out inside an input tag. This results in a reflected XSS vulnerability that attackers can exploit with a specially crafted URL. | |||||
CVE-2020-24917 | 1 Osticket | 1 Osticket | 2020-09-03 | 4.3 MEDIUM | 6.1 MEDIUM |
osTicket before 1.14.3 allows XSS via a crafted filename to DraftAjaxAPI::_uploadInlineImage() in include/ajax.draft.php. | |||||
CVE-2020-15154 | 1 Basercms | 1 Basercms | 2020-09-03 | 2.1 LOW | 7.3 HIGH |
baserCMS 4.3.6 and earlier is affected by Cross Site Scripting (XSS) via arbitrary script execution. Admin access is required to exploit this vulnerability. The affected components are: content_fields.php, content_info.php, content_options.php, content_related.php, index_list_tree.php, jquery.bcTree.js. The issue is fixed in version 4.3.7. | |||||
CVE-2020-13655 | 1 O-dyn | 1 Collabtive | 2020-09-03 | 4.3 MEDIUM | 6.1 MEDIUM |
An issue was discovered in Collabtive 3.0 and later. managefile.php is vulnerable to XSS: when the action parameter is set to movefile and the id parameter corresponds to a project the current user has access to, the file and target parameters are reflected. | |||||
CVE-2020-15155 | 1 Basercms | 1 Basercms | 2020-09-03 | 2.1 LOW | 7.3 HIGH |
baserCMS 4.3.6 and earlier is affected by Cross Site Scripting (XSS) via arbitrary script execution. Admin access is required to exploit this vulnerability. The affected components is toolbar.php. The issue is fixed in version 4.3.7. |